Crypto news

10.08.2026
19:11

Kimsuky arms itself with local AI: a new attack vector against the crypto industry

Lazarus Group КНДР хакеры

The North Korean hacker group Kimsuky, known for its attacks on the financial sector, has reached a fundamentally new level of technological evolution. According to my analysis of data from South Korean cybersecurity researchers, the group is actively integrating local artificial intelligence systems into its attack chains targeting cryptocurrency and financial companies.

A key feature of the new tactic is the use of local LLM environments based on the open platforms Ollama, GPT4All, and Msty. This is a fundamentally important point: such models operate fully offline and support the Retrieval-Augmented Generation method. In other words, operators can process sensitive data, including potential leaks from compromised systems, without sending requests to cloud services, which completely eliminates the possibility of traffic interception or anomaly detection through cloud providers.

Not only the models themselves have been found in the group's infrastructure, but also a whole arsenal of accompanying tools: libraries for embedding language models into their own software, the AI programming assistant Cursor, and speech recognition systems. This indicates that Kimsuky is not just experimenting but is building a full-fledged attack automation pipeline.

From experiments to combat deployment

It is important to emphasize that this is not about testing technology but about preparing for real combat operations. The group is betting on using ready-made open-source solutions rather than training its own models from scratch. This significantly reduces development time and allows for rapid adaptation of the toolkit to specific tasks—from generating phishing emails to analyzing large volumes of data stolen during breaches.

Of particular concern is the use of generative AI to create phishing documents. Some of these materials mimic official papers from a Korean investment AI platform, while featuring natural language and professional formatting. These are no longer mass mailings with errors—these are targeted, personalized attacks capable of deceiving even experienced employees of financial organizations.

I would note that this is yet another confirmation of a systemic threat. Previously, the crypto exchange Bybit already filed a civil lawsuit against North Korea and the Lazarus Group, which underscores the scale of the problem. In my understanding, the use of local AI is a strategic step that makes North Korean hackers' attacks even harder to detect. The industry urgently needs to revise its security protocols, focusing on behavioral analysis and monitoring of anomalous actions rather than only on signatures of known malware.